Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0045
MITRE ATT&CK Malware

ADVSTORESHELL (S0045)

AZZYEVILTOSSNETUISedreco
ShareXLinkedInRedditHN

[ADVSTORESHELL](https://attack.mitre.org/software/S0045) is a spying backdoor that has been used by [APT28](https://attack.mitre.org/groups/G0007) from at least 2012 to 2016. It is generally used for long-term espionage and is deployed on targets deemed interesting after a reconnaissance phase. (Citation: Kaspersky Sofacy) (Citation: ESET Sednit Part 2)

Platforms: Windows

▪Techniques implemented (23)

T1546.015Component Object Model HijackingT1082System Information DiscoveryT1056.001KeyloggingT1132.001Standard EncodingT1218.011Rundll32T1547.001Registry Run Keys / Startup FolderT1560Archive Collected DataT1070.004File DeletionT1074.001Local Data StagingT1029Scheduled TransferT1057Process DiscoveryT1059.003Windows Command ShellT1083File and Directory DiscoveryT1573.001Symmetric CryptographyT1071.001Web ProtocolsT1012Query RegistryT1120Peripheral Device DiscoveryT1112Modify RegistryT1027Obfuscated Files or InformationT1560.003Archive via Custom MethodT1106Native APIT1573.002Asymmetric CryptographyT1041Exfiltration Over C2 Channel

▪Used by groups (1)

G0007APT28
S0045on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.